Google Ads is down to two attribution models and GA4 defaults to data-driven — but for a peptide brand with a compliance gate, thin conversion volume, and touchpoints split across Google and Meta, picking the right model is only half the problem. Here's what actually fits, and what to check every month.
Pull up three dashboards for the same peptide brand on the same day — GA4's attribution report, the Google Ads "Conversions" column, and Meta Ads Manager — and you will get three different stories about what drove last month's revenue. None of them is lying. Each one is applying a different attribution model, to a different definition of a touchpoint, over a different lookback window, on a fraction of the traffic that third-party cookies and iOS privacy controls will actually let it see. For a mainstream ecommerce brand that's an annoyance. For a peptide or research-chemical brand running Google and Meta side by side, with a compliance disclaimer gate in the middle of the funnel and a monthly conversion count in the low hundreds, it's the difference between a media plan that compounds and one that just looks busy.
Most attribution content written for ecommerce assumes a clean, unrestricted setup: unlimited remarketing audiences, a checkout that's one click from the ad, and enough conversion volume that Google's and Meta's machine-learned models have plenty of signal to work with. None of that holds for a research-chemical or peptide brand.
Layer a longer consideration cycle on top — repeat-purchase and subscription customers who research for one to three weeks, compare two or three brands, and often re-enter through a different channel before they buy — and a single last-click number stops being a management tool. It becomes a number you report and privately don't trust.
The attribution landscape narrowed considerably over the past two years, and it's worth being precise about where things actually stand, because a lot of the advice still circulating online describes models that no longer exist.
Google has removed first-click, linear, time-decay, and position-based attribution from Google Ads. New conversion actions stopped being able to select those models earlier this year, and by this September every conversion action still running on one of them gets automatically migrated to data-driven attribution, whether the account owner asked for it or not. Google's stated reason was that adoption of those four models had fallen under 3% of accounts — most advertisers had already moved on. What's left in Google Ads is data-driven attribution (DDA), which is now the default for new conversion actions, and last-click, kept mainly as a fallback for accounts that genuinely don't have the volume to support modeling.
Data-driven attribution distributes credit across every touchpoint in the recorded path using a model trained on your account's own conversion patterns — it compares converting and non-converting paths and estimates each touchpoint's actual incremental contribution, rather than crediting whichever click happened last. That's a meaningfully better representation of a multi-touch, multi-week peptide buying journey than last-click, which routinely over-credits branded search and under-credits the awareness and consideration touchpoints that built the demand in the first place.
GA4 went through its own restructure this year. Attribution settings can now be configured independently for each conversion event rather than as a single property-wide setting, which is a real improvement if you're weighing a first-time purchase differently from a subscription renewal. The models available narrowed to match Google Ads: data-driven attribution (the default for event-scoped reporting), plus two last-click variants — paid-and-organic last click and Google-paid-channels last click. First-click, linear, time-decay, and position-based are gone from GA4 too.
The practical upshot is that GA4 and Google Ads are more alignable than they used to be, but they still won't match exactly — different time bases (conversion time versus interaction time), different eligible channel sets, and different attribution windows all produce a gap between the two reports. That gap isn't automatically a tracking error. It's expected. What you should be able to do is explain the size of it, not chase it to zero.
Meta attributes conversions on its own default window (commonly 7-day click, 1-day view, though this is configurable) using its own modeled view of the funnel — and it has no visibility into what Google Ads or GA4 are crediting for the same order. If a customer clicks a Meta ad, researches for a week, then converts from a branded Google search, both platforms will legitimately claim that sale under their own attribution logic. Sum "conversions" across Google Ads, Meta, and GA4 and you will always land above your actual order count from Shopify or your backend. That's not a bug in any one platform — it's the structural limit of single-platform, walled-garden attribution, and it's the reason cross-channel reporting has to reconcile against the store's own order data, not against the sum of ad platform dashboards.
This is where the restricted-category reality collides with how DDA actually functions. Data-driven attribution needs a meaningful trailing volume of conversions to build a reliable model — historically Google has cited a threshold in the neighborhood of 300 conversions in a trailing 30-day period for a conversion action to model well. Below that, the model either can't activate meaningfully or produces credit assignments that swing wildly month to month as a handful of orders shift the training data.
A lot of peptide and research-chemical brands never get near that number on a single conversion action, for reasons that have nothing to do with how good the brand or the media buying is: compliance-driven budget caps, a smaller addressable audience for the category, and the extra funnel friction from the disclaimer step all suppress raw conversion count relative to what a similarly-sized mainstream ecommerce account would see. This is the same thin-pool dynamic that shows up everywhere in restricted-category paid media — audience sizes, testing velocity, statistical significance windows — attribution modeling is just the latest place it bites.
Three things actually help here:
Every ecommerce brand is dealing with third-party cookie decay and iOS privacy limits. Peptide and research-chemical brands are dealing with it on top of a customer base that's more likely than average to reject cookie consent, run an ad blocker, or browse in Safari — where Intelligent Tracking Prevention caps cookie lifespans far below the 30-to-90-day windows attribution models want to reference. That combination is exactly why the signal-recovery layer — enhanced conversions, Consent Mode, and server-side tagging — matters more here than in most categories, not less.
Enhanced conversions work by capturing first-party identity data (email, phone, name and address) at the moment of conversion, hashing it with SHA-256, and matching it against Google's own logged-in user graph to connect the conversion back to the original ad click — even when the browser-side cookie that would normally do that job has already expired or was never set. Brands that implement this well typically see reported conversions rise 5-15% purely from recovered matches, and a healthy implementation shows roughly half or more of total conversions coming through as "enhanced." That recovered signal doesn't just add conversions — it feeds directly into how well data-driven attribution can model the path, because DDA can only credit touchpoints it can actually see.
Consent Mode, run in its Advanced configuration rather than Basic, keeps sending anonymous, cookieless signals to Google even from visitors who decline tracking consent — which lets Google build a statistical conversion model that estimates the volume being lost from the rejecting segment, instead of simply losing that data outright. For a category where consent-rejection rates skew high, this is the difference between attribution reports that undercount a predictable chunk of every month's traffic and reports that at least model around it.
Server-side tagging routes conversion events through a first-party domain instead of relying entirely on a browser-side pixel, which keeps ad blockers and browser tracking prevention from stripping the signal before it ever reaches Google or Meta, and extends how long first-party cookies survive. It's not a workaround for consent — it still respects whatever the visitor chose — but it closes the gap between what actually happened on the site and what the ad platforms are able to see happened.
We've written a dedicated breakdown of how to implement enhanced conversions specifically for a peptide ecommerce funnel without tripping compliance or platform review, which is worth reading alongside this piece if you haven't set this up yet.
Most peptide brands build their research-use disclaimer or jurisdiction gate as a straightforward compliance requirement and don't think about it again. But that interstitial sits directly in the path every paid click has to travel, and how it's built determines whether the click ID that identifies the ad, keyword, or creative survives to the actual conversion event.
The two failure modes we see most often: the gate redirects to a different subdomain or strips query parameters on the way through, silently dropping the gclid or fbclid before it ever reaches the page that fires the conversion tag — or the gate is served as a full page reload rather than an in-page interaction, adding a session boundary that some tracking configurations misread as a new, unattributed visit. Either one quietly degrades data-driven attribution's ability to model the path correctly, because the model is only as good as the touchpoints it can actually string together into one journey. Auditing that the gate preserves URL parameters through every redirect, and confirming the conversion tag still fires correctly after it, is a five-minute check that fixes a problem most brands don't know they have. It's part of the broader funnel work we cover in turning traffic into revenue for peptide brands — attribution accuracy and conversion rate optimization break down in a lot of the same places.
Attribution reporting can turn into an exercise in staring at numbers that move for reasons no one on the team can explain. Here's the monthly checklist we run for peptide and research-chemical accounts to keep it grounded in decisions instead of dashboard-watching:
Oney Studio was founded out of Google, and attribution modeling is one of the areas where that background changes how we approach an account — we're not treating data-driven attribution as a black box to accept on faith, and we're not defaulting to last-click because it's simpler to explain in a monthly report. We build the measurement layer (conversion action structure, enhanced conversions, Consent Mode, server-side tagging) before we scale spend on top of it, because scaling a media budget on top of broken signal just means scaling the noise. In one recent peptide brand engagement, fixing conversion tracking and attribution visibility was the prerequisite step before paid spend could scale efficiently at all — you can read the details in our peptide brand scaling case study. For the fuller picture of how attribution fits into the broader paid media approach for this category, see our guide to paid media strategy for peptide ecommerce, from first dollar spent through scale.
If your Google Ads and GA4 numbers don't agree, your Meta conversions don't reconcile with actual orders, or you're not sure whether your account has enough volume for data-driven attribution to be trustworthy, that's exactly the kind of audit worth having a second set of eyes run before you make a budget decision based on it.
Get a free 30-minute audit of your Google Ads or Meta Ads account. We’ll review compliance, structure, and growth opportunities — no strings attached.
Book a Free Audit